hacker-news · Crawled Jul 6, 2026

Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations

8 IoCs 3 Actors 3 CVEs
Read original article ↗

AI Summary

An Iranian hacking group linked to the Ministry of Intelligence and Security (MOIS), tracked as Cavern Manticore, has been using a new modular command-and-control (C2) framework named Cavern to target Israeli organizations, particularly in the IT and government sectors. The attack leverages DLL side-loading via SysAid's software update mechanism, deploying a trojanized DLL (uxtheme.dll) that communicates with a C2 server and downloads additional malicious modules. These modules enable reconnaissance, data theft, lateral movement, and tunneling, with a sophisticated .NET-based architecture using mixed compilation formats to hinder analysis. The group exploits trusted relationships in the software supply chain and has shifted from broad reconnaissance to targeted data exfiltration across Middle Eastern sectors.

AI-extracted · verify before operational use

Extracted Entities 6 found

Indicators of Compromise 8 extracted

Type Value Detail
Domain hospitalinstallation[[.]]com Details →
Filename uxtheme.dll Details →
Filename n-HTCommp.dll Details →
Filename mhm.dll Details →
Filename db.dll Details →
Filename ode.dll Details →
Filename n-ten.dll Details →
Filename n-sws.dll Details →

MITRE ATT&CK TTPs 137 techniques

T1003 OS Credential Dumping · Credential Access T1027 Obfuscated Files or Information · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.007 JavaScript · Execution T1071.001 Web Protocols · Command And Control T1074 Data Staged · Collection T1074.001 Local Data Staging · Collection T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1090.003 Multi-hop Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1219 Remote Access Software · Command And Control T1566 Phishing · Initial Access T1573.001 Symmetric Cryptography · Command And Control T1588 Obtain Capabilities · Resource Development T1071.004 DNS · Command And Control T1059.004 Unix Shell · Execution T1190 Exploit Public-Facing Application · Initial Access T1505.003 Web Shell · Persistence T1005 Data from Local System · Collection T1021 Remote Services · Lateral Movement T1021.001 Remote Desktop Protocol · Lateral Movement T1021.002 SMB/Windows Admin Shares · Lateral Movement T1021.003 Distributed Component Object Model · Lateral Movement T1021.004 SSH · Lateral Movement T1021.005 VNC · Lateral Movement T1021.006 Windows Remote Management · Lateral Movement T1021.007 Cloud Services · Lateral Movement T1021.008 Direct Cloud VM Connections · Lateral Movement T1021.009 T1021.009 T1021.010 T1021.010 T1021.011 T1021.011 T1021.012 T1021.012 T1021.013 T1021.013 T1021.014 T1021.014 T1021.015 T1021.015 T1021.016 T1021.016 T1021.017 T1021.017 T1021.018 T1021.018 T1021.019 T1021.019 T1021.020 T1021.020 T1021.021 T1021.021 T1021.022 T1021.022 T1021.023 T1021.023 T1021.024 T1021.024 T1021.025 T1021.025 T1021.026 T1021.026 T1021.027 T1021.027 T1021.028 T1021.028 T1021.029 T1021.029 T1021.030 T1021.030 T1021.031 T1021.031 T1021.032 T1021.032 T1021.033 T1021.033 T1021.034 T1021.034 T1021.035 T1021.035 T1021.036 T1021.036 T1021.037 T1021.037 T1021.038 T1021.038 T1021.039 T1021.039 T1021.040 T1021.040 T1021.041 T1021.041 T1021.042 T1021.042 T1021.043 T1021.043 T1021.044 T1021.044 T1021.045 T1021.045 T1021.046 T1021.046 T1021.047 T1021.047 T1021.048 T1021.048 T1021.049 T1021.049 T1021.050 T1021.050 T1021.051 T1021.051 T1021.052 T1021.052 T1021.053 T1021.053 T1021.054 T1021.054 T1021.055 T1021.055 T1021.056 T1021.056 T1021.057 T1021.057 T1021.058 T1021.058 T1021.059 T1021.059 T1021.060 T1021.060 T1021.061 T1021.061 T1021.062 T1021.062 T1021.063 T1021.063 T1021.064 T1021.064 T1021.065 T1021.065 T1021.066 T1021.066 T1021.067 T1021.067 T1021.068 T1021.068 T1021.069 T1021.069 T1021.070 T1021.070 T1021.071 T1021.071 T1021.072 T1021.072 T1021.073 T1021.073 T1021.074 T1021.074 T1021.075 T1021.075 T1021.076 T1021.076 T1021.077 T1021.077 T1021.078 T1021.078 T1021.079 T1021.079 T1021.080 T1021.080 T1021.081 T1021.081 T1021.082 T1021.082 T1021.083 T1021.083 T1021.084 T1021.084 T1021.085 T1021.085 T1021.086 T1021.086 T1021.087 T1021.087 T1021.088 T1021.088 T1021.089 T1021.089 T1021.090 T1021.090 T1021.091 T1021.091 T1021.092 T1021.092 T1021.093 T1021.093 T1021.094 T1021.094 T1021.095 T1021.095 T1021.096 T1021.096 T1021.097 T1021.097 T1021.098 T1021.098 T1021.099 T1021.099 T1021.100 T1021.100 T1027.002 Software Packing · Defense Evasion T1048 Exfiltration Over Alternative Protocol · Exfiltration T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059.005 Visual Basic · Execution T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.002 File Transfer Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1085 T1085 T1095 Non-Application Layer Protocol · Command And Control T1114.001 Local Email Collection · Collection T1484.002 Trust Modification · Defense Evasion